Search

Find a vulnerability

Search criteria

    45 vulnerabilities

    CVE-2026-14316 (GCVE-0-2026-14316)

    Vulnerability from cvelistv5 – Published: 2026-10-01 16:16 – Updated: 2026-10-01 16:32
    VLAI
    Title
    Heap buffer overflow in boks_sshd revoked-key error handling
    Summary
    The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 16:32 UTC
    CWE
    • CWE-122 - Heap-based buffer overflow
    Impacted products
    Vendor Product Version
    Fortra Core Privileged Access Manager (BoKS) Affected: 8.1.0.0 , < 8.1.0.30 (custom)
    Affected: 10.1.0.0 , < 10.1.1.0 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-14316",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T16:32:47.169777Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T16:32:54.604Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Core Privileged Access Manager (BoKS)",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "8.1.0.30",
                  "status": "affected",
                  "version": "8.1.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "10.1.1.0",
                  "status": "affected",
                  "version": "10.1.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This is reachable when RevokedKeys is configured and public-key authentication checks a revoked key or encounters an error while checking the revoked-keys file.\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eRevokedKeys must be configured, and the attacker must be able to initiate SSH public-key authentication with a key that is revoked or otherwise triggers an error in revoked-key checking.\u003c/span\u003e\u0026nbsp;\u003c/div\u003e"
                }
              ],
              "value": "This is reachable when RevokedKeys is configured and public-key authentication checks a revoked key or encounters an error while checking the revoked-keys file.\n\n\nRevokedKeys must be configured, and the attacker must be able to initiate SSH public-key authentication with a key that is revoked or otherwise triggers an error in revoked-key checking."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. T\u003cspan\u003ehe allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.\u0026nbsp;\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122 Heap-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T16:16:36.508Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-019"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to a patched version."
                }
              ],
              "value": "Upgrade to a patched version."
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Heap buffer overflow in boks_sshd revoked-key error handling",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-14316",
        "datePublished": "2026-10-01T16:16:36.508Z",
        "dateReserved": "2026-07-01T11:40:47.817Z",
        "dateUpdated": "2026-10-01T16:32:54.604Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9864 (GCVE-0-2026-9864)

    Vulnerability from cvelistv5 – Published: 2026-10-01 16:00 – Updated: 2026-10-01 16:16
    VLAI
    Title
    Fortra BoKS Server Agent adjoin machine-account password generation vulnerability
    Summary
    Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 16:16 UTC
    CWE
    • CWE-338 - Use of cryptographically weak Pseudo-Random number generator (PRNG)
    Impacted products
    Vendor Product Version
    Fortra Core Privileged Access Manager (BoKS) Affected: 8.1.0.0 , ≤ 8.1.0.29 (custom)
    Affected: 9.0.0.0 , ≤ 9.0.0.5 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9864",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T16:16:03.897430Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T16:16:15.483Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "modules": [
                "adjoin"
              ],
              "product": "Core Privileged Access Manager (BoKS)",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "8.1.0.29",
                  "status": "affected",
                  "version": "8.1.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.0.5",
                  "status": "affected",
                  "version": "9.0.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated."
                }
              ],
              "value": "Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can estimate when the password was generated."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-49",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-49 Password Brute Forcing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-338",
                  "description": "CWE-338 Use of cryptographically weak Pseudo-Random number generator (PRNG)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T16:00:25.899Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-018"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to a fixed boks-client release newer than 8.1.0.29 or 9.0.0.5, then rotate machine-account passwords generated by affected versions."
                }
              ],
              "value": "Upgrade to a fixed boks-client release newer than 8.1.0.29 or 9.0.0.5, then rotate machine-account passwords generated by affected versions."
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Fortra BoKS Server Agent adjoin machine-account password generation vulnerability",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Until fixed builds are deployed, avoid running adjoin join or autoupdate operations from affected versions. If automatic machine-account password renewal is enabled, disable it temporarily or ensure renewed passwords are rotated again after upgrading to a fixed version."
                }
              ],
              "value": "Until fixed builds are deployed, avoid running adjoin join or autoupdate operations from affected versions. If automatic machine-account password renewal is enabled, disable it temporarily or ensure renewed passwords are rotated again after upgrading to a fixed version."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-9864",
        "datePublished": "2026-10-01T16:00:25.899Z",
        "dateReserved": "2026-05-28T16:37:54.270Z",
        "dateUpdated": "2026-10-01T16:16:15.483Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-12627 (GCVE-0-2026-12627)

    Vulnerability from cvelistv5 – Published: 2026-10-01 15:29 – Updated: 2026-10-01 16:02
    VLAI
    Title
    Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability
    Summary
    Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 16:02 UTC
    CWE
    • CWE-121 - Stack-based buffer overflow
    Impacted products
    Vendor Product Version
    Fortra Fortra's Core Privileged Access Manager (BoKS) Affected: 8.1.0.0 , ≤ 8.1.0.23 (custom)
    Affected: 9.0.0.0 , ≤ 9.0.0.6 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-12627",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T16:02:18.897301Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T16:02:27.366Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "boks_autoregisterd"
              ],
              "product": "Fortra\u0027s Core Privileged Access Manager (BoKS)",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "8.1.0.23",
                  "status": "affected",
                  "version": "8.1.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.0.6",
                  "status": "affected",
                  "version": "9.0.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Fortra\u0027s Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing."
                }
              ],
              "value": "Fortra\u0027s Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T15:29:41.772Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-017"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to boks-server 8.1.0.24 or 9.0.0.7."
                }
              ],
              "value": "Upgrade to boks-server 8.1.0.24 or 9.0.0.7."
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Fortra\u0027s Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Restrict network access to boks_autoregisterd, which listens on port 6507 by default. If autoregistration is not required, disable the boks_autoregisterd service until fixed builds are installed."
                }
              ],
              "value": "Restrict network access to boks_autoregisterd, which listens on port 6507 by default. If autoregistration is not required, disable the boks_autoregisterd service until fixed builds are installed."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-12627",
        "datePublished": "2026-10-01T15:29:41.772Z",
        "dateReserved": "2026-06-18T15:02:55.446Z",
        "dateUpdated": "2026-10-01T16:02:27.366Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-79896 (GCVE-0-2026-79896)

    Vulnerability from cvelistv5 – Published: 2026-10-01 15:09 – Updated: 2026-10-01 16:02
    VLAI
    Title
    Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability
    Summary
    Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 16:02 UTC
    CWE
    Impacted products
    Vendor Product Version
    Fortra BoKS Manager Affected: 8.1.0.0 , ≤ 8.1.0.23 (custom)
    Affected: 9.0.0.0 , ≤ 9.0.0.6 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-79896",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T16:02:42.850473Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T16:02:49.186Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "modules": [
                "boks_portmux"
              ],
              "product": "BoKS Manager",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "8.1.0.23",
                  "status": "affected",
                  "version": "8.1.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.0.6",
                  "status": "affected",
                  "version": "9.0.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption."
                }
              ],
              "value": "Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-125",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-125 Flooding"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T15:09:21.099Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-016"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7."
                }
              ],
              "value": "Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7."
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Until a fixed release is installed, restrict network access to boks_portmux listeners to trusted systems."
                }
              ],
              "value": "Until a fixed release is installed, restrict network access to boks_portmux listeners to trusted systems."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-79896",
        "datePublished": "2026-10-01T15:09:21.099Z",
        "dateReserved": "2026-08-25T14:50:07.493Z",
        "dateUpdated": "2026-10-01T16:02:49.186Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-79898 (GCVE-0-2026-79898)

    Vulnerability from cvelistv5 – Published: 2026-10-01 14:57 – Updated: 2026-10-01 15:28
    VLAI
    Title
    Fortra BoKS Manager crlserver command injection vulnerability
    Summary
    Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 15:15 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    Impacted products
    Vendor Product Version
    Fortra BoKS Manager Affected: 8.1.0.0 , ≤ 8.1.0.23 (custom)
    Affected: 9.0.0.0 , ≤ 9.0.0.6 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-79898",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T15:15:26.791853Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T15:28:05.079Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "modules": [
                "crlserver"
              ],
              "product": "BoKS Manager",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "8.1.0.23",
                  "status": "affected",
                  "version": "8.1.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.0.6",
                  "status": "affected",
                  "version": "9.0.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003eThe issue affects deployments that process configured CRL URLs. Exploitation requires an authenticated user who can add a CRL URL through one of the supported administration paths. In BCC, the user requires the CRLS add ABAC right. In WSI, the client requires permission to call addCACRLURL for the target domain and sufficient downstream BCCAS authority, through either the caller\u0027s forwarded BoKS session or WSI\u0027s configured domain account. These are network-accessible paths and do not require local sudo or suexec access. A non-root user of the cacrl command-line path requires a suitable sudo or suexec rule, which may be narrowly scoped to cacrl. Scheduled CRL import processes the URL automatically; a separately permitted download operation may also trigger processing.\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "The issue affects deployments that process configured CRL URLs. Exploitation requires an authenticated user who can add a CRL URL through one of the supported administration paths. In BCC, the user requires the CRLS add ABAC right. In WSI, the client requires permission to call addCACRLURL for the target domain and sufficient downstream BCCAS authority, through either the caller\u0027s forwarded BoKS session or WSI\u0027s configured domain account. These are network-accessible paths and do not require local sudo or suexec access. A non-root user of the cacrl command-line path requires a suitable sudo or suexec rule, which may be narrowly scoped to cacrl. Scheduled CRL import processes the URL automatically; a separately permitted download operation may also trigger processing."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule."
                }
              ],
              "value": "Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88: OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T14:57:28.382Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-015"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003eUpgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7, as appropriate for the installed maintenance line.\u0026nbsp;\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7, as appropriate for the installed maintenance line."
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Fortra BoKS Manager crlserver command injection vulnerability",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-79898",
        "datePublished": "2026-10-01T14:57:28.382Z",
        "dateReserved": "2026-08-25T14:50:10.463Z",
        "dateUpdated": "2026-10-01T15:28:05.079Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-79899 (GCVE-0-2026-79899)

    Vulnerability from cvelistv5 – Published: 2026-10-01 14:37 – Updated: 2026-10-01 15:28
    VLAI
    Title
    Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability
    Summary
    Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 15:15 UTC
    CWE
    • CWE-377 - Insecure Temporary File
    Impacted products
    Vendor Product Version
    Fortra BoKS Manager Affected: 8.1.0.0 , ≤ 8.1.0.23 (custom)
    Affected: 9.0.0.0 , ≤ 9.0.0.6 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-79899",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T15:15:16.158691Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T15:28:05.358Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "bccgethostcert"
              ],
              "product": "BoKS Manager",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "8.1.0.23",
                  "status": "affected",
                  "version": "8.1.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.0.6",
                  "status": "affected",
                  "version": "9.0.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation."
                }
              ],
              "value": "Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-155",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-155 Screen Temporary Files for Sensitive Information"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 7.9,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-377",
                  "description": "CWE-377: Insecure Temporary File",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T14:37:23.805Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-014"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to boks-server 8.1.0.24 or 9.0.0.7."
                }
              ],
              "value": "Upgrade to boks-server 8.1.0.24 or 9.0.0.7."
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Until a fixed release is installed, restrict local access to the BoKS Master and BOKS_tmp, invoke bccgethostcert with a restrictive umask such as 077, and securely remove any stale bcccax.* or bcccreds.* files from BOKS_tmp."
                }
              ],
              "value": "Until a fixed release is installed, restrict local access to the BoKS Master and BOKS_tmp, invoke bccgethostcert with a restrictive umask such as 077, and securely remove any stale bcccax.* or bcccreds.* files from BOKS_tmp."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-79899",
        "datePublished": "2026-10-01T14:37:23.805Z",
        "dateReserved": "2026-08-25T14:50:11.492Z",
        "dateUpdated": "2026-10-01T15:28:05.358Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-79900 (GCVE-0-2026-79900)

    Vulnerability from cvelistv5 – Published: 2026-10-01 14:11 – Updated: 2026-10-01 14:42
    VLAI
    Title
    Heap overflow in KSL checksum initialization
    Summary
    boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:41 UTC
    CWE
    Impacted products
    Vendor Product Version
    Fortra BoKS Manager boks-server Affected: 0 , < 8.1.0.24 (semver)
    Affected: 0 , < 9.0.0.7 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-79900",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:41:25.553335Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:42:09.954Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "BoKS Manager boks-server",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "8.1.0.24",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "9.0.0.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The attacker must have a valid KSL log-client identity accepted by boks_ksllogsd, network access to the KSL log service, and the ability to send a KSLSTART message with an oversized but OpenSSL-recognized MD value. An unauthenticated network client cannot reach the vulnerable message-processing path."
                }
              ],
              "value": "The attacker must have a valid KSL log-client identity accepted by boks_ksllogsd, network access to the KSL log service, and the ability to send a KSLSTART message with an oversized but OpenSSL-recognized MD value. An unauthenticated network client cannot reach the vulnerable message-processing path."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation."
                }
              ],
              "value": "boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-100",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-100 Overflow Buffers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T14:11:55.071Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-013"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7, as appropriate for the installed maintenance line, and ensure the updated boks_ksllogsd is running."
                }
              ],
              "value": "Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7, as appropriate for the installed maintenance line, and ensure the updated boks_ksllogsd is running."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Heap overflow in KSL checksum initialization",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-79900",
        "datePublished": "2026-10-01T14:11:55.071Z",
        "dateReserved": "2026-08-25T14:50:14.032Z",
        "dateUpdated": "2026-10-01T14:42:09.954Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-79901 (GCVE-0-2026-79901)

    Vulnerability from cvelistv5 – Published: 2026-10-01 13:52 – Updated: 2026-10-01 14:43
    VLAI
    Title
    Predictable Active Directory service-account passwords in BoKS Manager
    Summary
    In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:42 UTC
    CWE
    • CWE-338 - Use of cryptographically weak Pseudo-Random number generator (PRNG)
    Impacted products
    Vendor Product Version
    Fortra BoKS Manager boks-server Affected: 0 , < 9.0.0.6 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-79901",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:42:41.970090Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:43:07.294Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "BoKS Manager boks-server",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "9.0.0.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Only BoKS Manager deployments using BoKS keytab management to manage Active Directory service accounts are affected. Deployments that do not use BoKS keytab management are not affected. Administrator-supplied initial service-account passwords are not generated through the vulnerable code path and are not affected."
                }
              ],
              "value": "Only BoKS Manager deployments using BoKS keytab management to manage Active Directory service accounts are affected. Deployments that do not use BoKS keytab management are not affected. Administrator-supplied initial service-account passwords are not generated through the vulnerable code path and are not affected."
            },
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Exploitation requires knowledge of the affected service principal, an estimate of the password-change time, and suitable Kerberos ticket material. A standard authenticated Active Directory account can ordinarily request a service ticket for an SPN assigned to the affected account; administrative access to BoKS, the service host, or its keytab is not normally required. A previously captured service ticket can alternatively provide offline verification material."
                }
              ],
              "value": "Exploitation requires knowledge of the affected service principal, an estimate of the password-change time, and suitable Kerberos ticket material. A standard authenticated Active Directory account can ordinarily request a service ticket for an SPN assigned to the affected account; administrative access to BoKS, the service host, or its keytab is not normally required. A previously captured service ticket can alternatively provide offline verification material."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline."
                }
              ],
              "value": "In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-49",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-49 Password Brute Forcing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-338",
                  "description": "CWE-338 Use of cryptographically weak Pseudo-Random number generator (PRNG)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T13:52:27.046Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-012"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade the active BoKS Master to boks-server 9.0.0.7 and restart BoKS before generating replacement passwords."
                }
              ],
              "value": "Upgrade the active BoKS Master to boks-server 9.0.0.7 and restart BoKS before generating replacement passwords."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Predictable Active Directory service-account passwords in BoKS Manager",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Installing the update does not secure passwords generated by an affected release. Rotate all affected or uncertain service-account passwords through BoKS keytab management and confirm distribution of the new key version. After the Active Directory domain\u0027s configured maximum service-ticket lifetime plus clock-skew allowance has elapsed, rebuild affected keytabs during a maintenance window so they retain only the current key version. Redistribute and verify the keytabs, restart or reload dependent services as required, and test Kerberos authentication. If compromise is suspected, rotate and rebuild immediately rather than waiting for existing tickets to expire."
                }
              ],
              "value": "Installing the update does not secure passwords generated by an affected release. Rotate all affected or uncertain service-account passwords through BoKS keytab management and confirm distribution of the new key version. After the Active Directory domain\u0027s configured maximum service-ticket lifetime plus clock-skew allowance has elapsed, rebuild affected keytabs during a maintenance window so they retain only the current key version. Redistribute and verify the keytabs, restart or reload dependent services as required, and test Kerberos authentication. If compromise is suspected, rotate and rebuild immediately rather than waiting for existing tickets to expire."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-79901",
        "datePublished": "2026-10-01T13:52:27.046Z",
        "dateReserved": "2026-08-25T14:50:15.178Z",
        "dateUpdated": "2026-10-01T14:43:07.294Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-15913 (GCVE-0-2026-15913)

    Vulnerability from cvelistv5 – Published: 2026-09-09 21:18 – Updated: 2026-09-10 13:49
    VLAI
    Title
    Path Traversal in Fortra's GoAnywhere MFT Endpoint
    Summary
    In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-10 13:49 UTC
    CWE
    • CWE-23 - Relative path traversal
    References
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere MFT Affected: 0 , < 7.10.2 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-15913",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-10T13:49:14.002969Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T13:49:34.773Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Secure Mail",
                "Secure Folders",
                "File System"
              ],
              "product": "GoAnywhere MFT",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "7.10.2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "xtromera (Zerosploit) https://www.zerosploit.co/"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "ZeyadZonkorany (Zerosploit) https://www.zerosploit.co/"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "0xkalawy (Zerosploit) https://www.zerosploit.co/"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In versions prior to 7.10.2 a path traversal vulnerability in the\u0026nbsp;/attachRemoteFiles endpoint\u0026nbsp;of Fortra\u0027s GoAnywhere MFT allows Web Users with both\u0026nbsp;Secure Folders and Secure Mail permissions\u0026nbsp;to escape their sandboxed home directory, achieving arbitrary file read."
                }
              ],
              "value": "In versions prior to 7.10.2 a path traversal vulnerability in the\u00a0/attachRemoteFiles endpoint\u00a0of Fortra\u0027s GoAnywhere MFT allows Web Users with both\u00a0Secure Folders and Secure Mail permissions\u00a0to escape their sandboxed home directory, achieving arbitrary file read."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-23",
                  "description": "CWE-23 Relative path traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-09T21:18:54.261Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-011"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to a remediated version (version 7.10.2 or later)."
                }
              ],
              "value": "Upgrade to a remediated version (version 7.10.2 or later)."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Path Traversal in Fortra\u0027s GoAnywhere MFT Endpoint",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-15913",
        "datePublished": "2026-09-09T21:18:54.261Z",
        "dateReserved": "2026-07-15T19:34:18.897Z",
        "dateUpdated": "2026-09-10T13:49:34.773Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-12164 (GCVE-0-2026-12164)

    Vulnerability from cvelistv5 – Published: 2026-06-23 22:15 – Updated: 2026-06-24 13:15
    VLAI
    Title
    Privilege Escalation in Fortra File Integrity Monitoring (FIM)
    Summary
    Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool import command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-24 13:15 UTC
    CWE
    • CWE-266 - Incorrect privilege assignment
    Impacted products
    Vendor Product Version
    Fortra File Integrity Monitoring (FIM) Affected: 0 , < 9.4.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-12164",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-24T13:15:29.228755Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-24T13:15:39.352Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "File Integrity Monitoring (FIM)",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "9.4.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the\u0026nbsp;tetool import\u0026nbsp;command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships."
                }
              ],
              "value": "Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the\u00a0tetool import\u00a0command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 4.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "CWE-266 Incorrect privilege assignment",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-23T22:25:18.710Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-010"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to version 9.4.0 or later."
                }
              ],
              "value": "Upgrade to version 9.4.0 or later."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Privilege Escalation in Fortra File Integrity Monitoring (FIM)",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-12164",
        "datePublished": "2026-06-23T22:15:37.683Z",
        "dateReserved": "2026-06-12T19:31:35.041Z",
        "dateUpdated": "2026-06-24T13:15:39.352Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-12163 (GCVE-0-2026-12163)

    Vulnerability from cvelistv5 – Published: 2026-06-23 22:06 – Updated: 2026-06-24 15:35
    VLAI
    Title
    Stored XSS in Fortra File Integrity Monitoring (FIM)
    Summary
    Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticated user with sufficient privileges to create or modify affected node or database configuration fields could store script content that may be rendered as HTML instead of safely escaped text when the affected Asset View UI content is displayed.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-24 15:34 UTC
    CWE
    • CWE-79 - Improper neutralization of input during web page generation ('cross-site scripting')
    Impacted products
    Vendor Product Version
    Fortra File Integrity Monitoring (FIM) Affected: 0 , < 9.4.0.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-12163",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-24T15:34:44.691281Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-24T15:35:18.070Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "File Integrity Monitoring (FIM)",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "9.4.0.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eFortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticated user with sufficient privileges to create or modify affected node or database configuration fields could store script content that may be rendered as HTML instead of safely escaped text when the affected Asset View UI content is displayed.\u003cspan\u003e\u003cbr\u003e\u003c/span\u003e\u003cbr\u003e\u003c/div\u003e"
                }
              ],
              "value": "Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticated user with sufficient privileges to create or modify affected node or database configuration fields could store script content that may be rendered as HTML instead of safely escaped text when the affected Asset View UI content is displayed."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-592",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-592 Stored XSS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-23T22:35:15.965Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-009"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to version 9.4.0.1 or later."
                }
              ],
              "value": "Upgrade to version 9.4.0.1 or later."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Stored XSS in Fortra File Integrity Monitoring (FIM)",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-12163",
        "datePublished": "2026-06-23T22:06:04.351Z",
        "dateReserved": "2026-06-12T19:31:33.795Z",
        "dateUpdated": "2026-06-24T15:35:18.070Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9863 (GCVE-0-2026-9863)

    Vulnerability from cvelistv5 – Published: 2026-06-15 15:17 – Updated: 2026-06-15 16:08
    VLAI
    Title
    Core Privileged Access Manager (BoKS) upgrade tooling command injection vulnerability
    Summary
    Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-15 16:08 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    Fortra Core Privileged Access Manager (BoKS) Affected: boks-server 8.1.0.0 , ≤ boks-server 8.1.0.22 (custom)
    Affected: boks-server 9.0.0.0 , ≤ boks-server 9.0.0.4 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9863",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-15T16:08:50.051689Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-15T16:08:58.885Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "boks_upgrade_upgrade",
                "boks_upgrade_patch"
              ],
              "product": "Core Privileged Access Manager (BoKS)",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "boks-server 8.1.0.22",
                  "status": "affected",
                  "version": "boks-server 8.1.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "boks-server 9.0.0.4",
                  "status": "affected",
                  "version": "boks-server 9.0.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Fortra internal security assessment"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eFortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.\u003c/p\u003e"
                }
              ],
              "value": "Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-248",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-248 Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T15:18:31.697Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-008"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eUpgrade to boks-server 8.1.0.23 or 9.0.0.5.\u003c/p\u003e"
                }
              ],
              "value": "Upgrade to boks-server 8.1.0.23 or 9.0.0.5."
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2026-06-01T00:00:00.000Z",
              "value": "Issue validated and fixes prepared for BOKS-900 and BOKS81-hotfix branches."
            }
          ],
          "title": "Core Privileged Access Manager (BoKS) upgrade tooling command injection vulnerability",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eUntil fixed builds are deployed, only run BoKS client upgrade or patch operations for legacy tar-based client installations against trusted clients. Avoid running boks_upgrade upgrade or patch operations for legacy tar-installed clients that may be compromised or controlled by an untrusted party.\u003c/p\u003e"
                }
              ],
              "value": "Until fixed builds are deployed, only run BoKS client upgrade or patch operations for legacy tar-based client installations against trusted clients. Avoid running boks_upgrade upgrade or patch operations for legacy tar-installed clients that may be compromised or controlled by an untrusted party."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-9863",
        "datePublished": "2026-06-15T15:17:19.607Z",
        "dateReserved": "2026-05-28T16:37:53.223Z",
        "dateUpdated": "2026-06-15T16:08:58.885Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9862 (GCVE-0-2026-9862)

    Vulnerability from cvelistv5 – Published: 2026-06-15 15:10 – Updated: 2026-06-15 16:09
    VLAI
    Title
    Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerability
    Summary
    Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-15 16:09 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    Fortra Core Privileged Access Manager (BoKS) Affected: boks-server 8.1.0.0 , ≤ boks-server 8.1.0.22 (custom)
    Affected: boks-server 9.0.0.0 , ≤ boks-server 9.0.0.4 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9862",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-15T16:09:18.347930Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-15T16:09:28.297Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "boks_autoregisterd"
              ],
              "product": "Core Privileged Access Manager (BoKS)",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "boks-server 8.1.0.22",
                  "status": "affected",
                  "version": "boks-server 8.1.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "boks-server 9.0.0.4",
                  "status": "affected",
                  "version": "boks-server 9.0.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Fortra internal security assessment"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eFortra\u0027s\u0026nbsp;\nCore Privileged Access Manager (BoKS)\u0026nbsp;contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.\u003c/p\u003e"
                }
              ],
              "value": "Fortra\u0027s\u00a0\nCore Privileged Access Manager (BoKS)\u00a0contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-248",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-248 Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T15:18:11.644Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-007"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eUpgrade to boks-server 8.1.0.23 or 9.0.0.5.\u003c/p\u003e"
                }
              ],
              "value": "Upgrade to boks-server 8.1.0.23 or 9.0.0.5."
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerability",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eRestrict network access to boks_autoregisterd, which listens on port 6507 by default, until fixed builds are deployed.\u0026nbsp;\u003c/p\u003e\u003cp\u003eAnother workaround for both boks-server 8.1 and 9.0 is to disable the service in the boksinit configuration. On the BoKS Master, edit\u003c/p\u003e\u003cp\u003e\u003cspan\u003e$BOKS_var/internal/boksinit/master\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan\u003eand comment out the line\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan\u003e`autoregisterd:300:1:0:respawn::$BOKS_lib/boks_autoregisterd -xn`\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan\u003eby prefixing it with\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan\u003e`#`;\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan\u003ethen make boks_init reread the file, for example by running\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan\u003e`kill -HUP $(cat $BOKS_var/run/boks_init)`,\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan\u003eor restart BoKS. This stops boks_autoregisterd and prevents it from being respawned; autoregistration is unavailable until the row is restored.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "Restrict network access to boks_autoregisterd, which listens on port 6507 by default, until fixed builds are deployed.\u00a0\n\n\n\nAnother workaround for both boks-server 8.1 and 9.0 is to disable the service in the boksinit configuration. On the BoKS Master, edit\n\n\n\n$BOKS_var/internal/boksinit/master\u00a0\n\n\n\nand comment out the line\u00a0\n\n\n\n`autoregisterd:300:1:0:respawn::$BOKS_lib/boks_autoregisterd -xn`\u00a0\n\n\n\nby prefixing it with\u00a0\n\n\n\n`#`;\u00a0\n\n\n\nthen make boks_init reread the file, for example by running\u00a0\n\n\n\n`kill -HUP $(cat $BOKS_var/run/boks_init)`,\u00a0\n\n\n\nor restart BoKS. This stops boks_autoregisterd and prevents it from being respawned; autoregistration is unavailable until the row is restored."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-9862",
        "datePublished": "2026-06-15T15:10:08.708Z",
        "dateReserved": "2026-05-28T16:37:50.792Z",
        "dateUpdated": "2026-06-15T16:09:28.297Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-1089 (GCVE-0-2026-1089)

    Vulnerability from cvelistv5 – Published: 2026-04-21 14:14 – Updated: 2026-04-21 15:00
    VLAI
    Title
    User‑Controlled HTTP Header In Fortra's GoAnywhere MFT Allows Arbitrary DNS Lookups
    Summary
    User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-04-21 15:00 UTC
    CWE
    • CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere MFT Affected: 0 , < 7.10.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-1089",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-04-21T15:00:15.290199Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-21T15:00:35.492Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GoAnywhere MFT",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "7.10.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "User\u2011Controlled HTTP Header in Fortra\u0027s GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as\u0026nbsp;DNS Rebinding and Information Disclosure."
                }
              ],
              "value": "User\u2011Controlled HTTP Header in Fortra\u0027s GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as\u00a0DNS Rebinding and Information Disclosure."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-142",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-142 DNS Cache Poisoning"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-21T14:14:58.244Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-005"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to a remediated version (version 7.10.0 or later)."
                }
              ],
              "value": "Upgrade to a remediated version (version 7.10.0 or later)."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "User\u2011Controlled HTTP Header In Fortra\u0027s GoAnywhere MFT Allows Arbitrary DNS Lookups",
          "x_generator": {
            "engine": "Vulnogram 1.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-1089",
        "datePublished": "2026-04-21T14:14:58.244Z",
        "dateReserved": "2026-01-16T21:03:16.471Z",
        "dateUpdated": "2026-04-21T15:00:35.492Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-0972 (GCVE-0-2026-0972)

    Vulnerability from cvelistv5 – Published: 2026-04-21 14:14 – Updated: 2026-04-29 19:32
    VLAI
    Title
    HTML Injection possible in system generated emails in Fortra's GoAnywhere MFT
    Summary
    HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-04-21 19:27 UTC
    CWE
    • CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere MFT Affected: 0 , < 7.10.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-0972",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-04-21T19:27:17.226262Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-21T19:27:23.897Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2026-04-29T19:32:13.201Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://seclists.org/fulldisclosure/2026/Apr/8"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "GoAnywhere MFT",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "7.10.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Philipp Schweinzer (SBA Research) https://www.sba-research.org/"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "HTML injection is possible in system generated emails in Fortra\u0027s GoAnywhere MFT prior to 7.10.0.\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eNote: The title, details, and description of this CVE were corrected post-publishing.\u003c/div\u003e"
                }
              ],
              "value": "HTML injection is possible in system generated emails in Fortra\u0027s GoAnywhere MFT prior to 7.10.0.\n\n\nNote: The title, details, and description of this CVE were corrected post-publishing."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-153",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-153 Input Data Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-22T18:55:20.563Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-006"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to patched version (7.10.0 or later)."
                }
              ],
              "value": "Upgrade to patched version (7.10.0 or later)."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "HTML Injection possible in system generated emails in Fortra\u0027s GoAnywhere MFT",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Reduce access to the system."
                }
              ],
              "value": "Reduce access to the system."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-0972",
        "datePublished": "2026-04-21T14:14:38.146Z",
        "dateReserved": "2026-01-14T23:07:29.797Z",
        "dateUpdated": "2026-04-29T19:32:13.201Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-0971 (GCVE-0-2026-0971)

    Vulnerability from cvelistv5 – Published: 2026-04-21 14:14 – Updated: 2026-04-21 19:26
    VLAI
    Title
    GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout
    Summary
    An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-04-21 19:26 UTC
    CWE
    • CWE-613 - Insufficient session expiration
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere MFT Affected: 0 , < 7.10.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-0971",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-04-21T19:26:48.832583Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-21T19:26:58.470Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows",
                "MacOS",
                "Linux"
              ],
              "product": "GoAnywhere MFT",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "7.10.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An improper session timeout issue in Fortra\u0027s GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page."
                }
              ],
              "value": "An improper session timeout issue in Fortra\u0027s GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-613",
                  "description": "CWE-613 Insufficient session expiration",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-21T14:14:23.423Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://fortra.com/security/advisories/product-security/fi-2025-013"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update to version 7.10.0 or higher of GoAnywhere MFT"
                }
              ],
              "value": "Update to version 7.10.0 or higher of GoAnywhere MFT"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout",
          "x_generator": {
            "engine": "Vulnogram 1.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-0971",
        "datePublished": "2026-04-21T14:14:23.423Z",
        "dateReserved": "2026-01-14T22:56:32.772Z",
        "dateUpdated": "2026-04-21T19:26:58.470Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-14362 (GCVE-0-2025-14362)

    Vulnerability from cvelistv5 – Published: 2026-04-21 14:14 – Updated: 2026-04-21 19:33
    VLAI
    Title
    GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances
    Summary
    The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-04-21 19:33 UTC
    CWE
    • CWE-307 - Improper restriction of excessive authentication attempts
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere MFT Affected: 0 , < 7.10.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-14362",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-04-21T19:33:27.357827Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-21T19:33:35.079Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GoAnywhere MFT",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "7.10.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The login limit is not enforced on the\u0026nbsp;SFTP service of Fortra\u0027s GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force."
                }
              ],
              "value": "The login limit is not enforced on the\u00a0SFTP service of Fortra\u0027s GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-49",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-49 Password Brute Forcing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "CWE-307 Improper restriction of excessive authentication attempts",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-21T14:14:08.492Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://fortra.com/security/advisories/product-security/FI-2026-002"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to patched version."
                }
              ],
              "value": "Upgrade to patched version."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances",
          "x_generator": {
            "engine": "Vulnogram 1.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2025-14362",
        "datePublished": "2026-04-21T14:14:08.492Z",
        "dateReserved": "2025-12-09T17:26:54.658Z",
        "dateUpdated": "2026-04-21T19:33:35.079Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1241 (GCVE-0-2025-1241)

    Vulnerability from cvelistv5 – Published: 2026-04-21 14:10 – Updated: 2026-04-21 19:33
    VLAI
    Title
    Encryption vulnerable to brute-force decryption in GoAnywhere MFT
    Summary
    Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-04-21 19:32 UTC
    CWE
    • CWE-326 - Inadequate Encryption Strength
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere MFT Affected: 0 , < 7.10.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1241",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-04-21T19:32:52.852629Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-21T19:33:03.005Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows",
                "Linux",
                "MacOS"
              ],
              "product": "GoAnywhere MFT",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "7.10.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Robin Wolters, Secura"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Encrypted values in Fortra\u0027s GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which\u0026nbsp;allows admin users to brute-force decryption of data."
                }
              ],
              "value": "Encrypted values in Fortra\u0027s GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which\u00a0allows admin users to brute-force decryption of data."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-20",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-20 Encryption Brute Forcing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-326",
                  "description": "CWE-326 Inadequate Encryption Strength",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-21T14:10:09.505Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://fortra.com/security/advisories/product-security/FI-2026-001"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to patched version."
                }
              ],
              "value": "Upgrade to patched version."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Encryption vulnerable to brute-force decryption in GoAnywhere MFT",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Restrict access to Admin Client."
                }
              ],
              "value": "Restrict access to Admin Client."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2025-1241",
        "datePublished": "2026-04-21T14:10:09.505Z",
        "dateReserved": "2025-02-11T23:19:04.818Z",
        "dateUpdated": "2026-04-21T19:33:03.005Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-2636 (GCVE-0-2026-2636)

    Vulnerability from cvelistv5 – Published: 2026-02-25 18:57 – Updated: 2026-02-26 15:56
    VLAI
    Title
    Denial of Service in Microsoft OS
    Summary
    This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the KeBugCheckEx function, allowing an unprivileged user to trigger a system crash. Microsoft silently fixed this vulnerability in the September 2025 cumulative update for Windows 11 2024 LTSC and Windows Server 2025. Windows 25H2 (released in September) was released with the patch. Windows 1123h2 and earlier versions remain vulnerable.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-02-26 15:56 UTC
    CWE
    • CWE-159 - Improper Handling of Invalid Use of Special Elements
    Impacted products
    Vendor Product Version
    Microsoft Windows OS Affected: 0 , < 25H2 (semver)
    Affected: 0 , ≤ 1123h2 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-2636",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-26T15:56:12.707562Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T15:56:55.089Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "Windows OS",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "25H2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "1123h2",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This vulnerability is caused by a CWE\u2011159: \"Improper Handling of Invalid Use of Special Elements\" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the KeBugCheckEx function, allowing an unprivileged user to trigger a system crash. Microsoft silently fixed this vulnerability in the September 2025 cumulative update for Windows 11 2024 LTSC and Windows Server 2025. Windows 25H2 (released in September) was released with the patch. Windows 1123h2 and earlier versions remain vulnerable."
                }
              ],
              "value": "This vulnerability is caused by a CWE\u2011159: \"Improper Handling of Invalid Use of Special Elements\" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the KeBugCheckEx function, allowing an unprivileged user to trigger a system crash. Microsoft silently fixed this vulnerability in the September 2025 cumulative update for Windows 11 2024 LTSC and Windows Server 2025. Windows 25H2 (released in September) was released with the patch. Windows 1123h2 and earlier versions remain vulnerable."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-153",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-153 Input Data Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-159",
                  "description": "CWE-159  Improper Handling of Invalid Use of Special Elements",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-02-25T18:57:02.962Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/research/fr-2026-001"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Denial of Service in Microsoft OS",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2026-2636",
        "datePublished": "2026-02-25T18:57:02.962Z",
        "dateReserved": "2026-02-17T18:49:03.493Z",
        "dateUpdated": "2026-02-26T15:56:55.089Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-13532 (GCVE-0-2025-13532)

    Vulnerability from cvelistv5 – Published: 2025-12-16 20:01 – Updated: 2025-12-16 20:23
    VLAI
    Title
    Weak Password Hash in Core Privileged Access Manager (BoKS)
    Summary
    Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms.  This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-16 20:18 UTC
    CWE
    • CWE-916 - Use of Password Hash With Insufficient Computational Effort
    Impacted products
    Vendor Product Version
    Fortra Core Privileged Access Manager (BoKS) Affected: This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain. The affected platforms are: Debian 11, 12, 13, RedHat 9, 10 and Ubuntu 24.
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-13532",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-16T20:18:38.616690Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-16T20:23:51.768Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Linux"
              ],
              "product": "Core Privileged Access Manager (BoKS)",
              "vendor": "Fortra",
              "versions": [
                {
                  "status": "affected",
                  "version": "This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain. The affected platforms are: Debian 11, 12, 13, RedHat 9, 10 and Ubuntu 24."
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Insecure defaults in the Server Agent component of Fortra\u0027s Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. \u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThis issue a\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003effects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.\u003c/span\u003e"
                }
              ],
              "value": "Insecure defaults in the Server Agent component of Fortra\u0027s Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. \u00a0This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-112",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-112 Brute Force"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.2,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-916",
                  "description": "CWE-916 Use of Password Hash With Insufficient Computational Effort",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-16T20:01:02.743Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2025-014"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to BoKS Server Agent 9.0.0.4.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Upgrade to BoKS Server Agent 9.0.0.4."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Weak Password Hash in Core Privileged Access Manager (BoKS)",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Configure the OS to use SHA512 rather than yescrypt.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Configure the OS to use SHA512 rather than yescrypt."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2025-13532",
        "datePublished": "2025-12-16T20:01:02.743Z",
        "dateReserved": "2025-11-21T21:04:44.245Z",
        "dateUpdated": "2025-12-16T20:23:51.768Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-8148 (GCVE-0-2025-8148)

    Vulnerability from cvelistv5 – Published: 2025-12-05 20:56 – Updated: 2025-12-05 21:48
    VLAI
    Title
    CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT
    Summary
    An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-05 21:48 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere MFT Affected: 0 , < 7.9.0 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-8148",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-05T21:48:36.023662Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-05T21:48:44.070Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows",
                "MacOS",
                "Linux"
              ],
              "product": "GoAnywhere MFT",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "7.9.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An Improper Access Control in the SFTP service in Fortra\u0027s GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key."
                }
              ],
              "value": "An Improper Access Control in the SFTP service in Fortra\u0027s GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-180",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.2,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-05T21:00:51.454Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2025-013"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to remediated version.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Upgrade to remediated version."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Remove any SSH Keys assigned to Web Users that are configured for Password-only authentication to the SFTP service.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Remove any SSH Keys assigned to Web Users that are configured for Password-only authentication to the SFTP service."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2025-8148",
        "datePublished": "2025-12-05T20:56:05.135Z",
        "dateReserved": "2025-07-24T21:27:23.294Z",
        "dateUpdated": "2025-12-05T21:48:44.070Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-10035 (GCVE-0-2025-10035)

    Vulnerability from cvelistv5 – Published: 2025-09-18 22:01 – Updated: 2026-08-04 03:55
    VLAI CISA Previdian
    Title
    Deserialization Vulnerability in GoAnywhere MFT's License Servlet
    Summary
    A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-09-19 00:00 UTC
    CWE
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    • CWE-502 - Deserialization of Untrusted Data
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere MFT Affected: 0 , ≤ 7.8.3 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-10035",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-09-19T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2025-09-29",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-10035"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-04T03:55:56.207Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-10035"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2025-09-29T00:00:00.000Z",
                "value": "CVE-2025-10035 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "platforms": [
                "Linux",
                "Windows",
                "MacOS"
              ],
              "product": "GoAnywhere MFT",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "7.8.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A deserialization vulnerability in the License Servlet of Fortra\u0027s GoAnywhere MFT allows an actor with a validly forged license response signature to \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003edeserialize an arbitrary actor-controlled object, possibly leading to command injection.\u003c/span\u003e"
                }
              ],
              "value": "A deserialization vulnerability in the License Servlet of Fortra\u0027s GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-248",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-248 Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502 Deserialization of Untrusted Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-18T22:43:41.684Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2025-012"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to a patched version (the latest release 7.8.4, or the Sustain Release 7.6.3)"
                }
              ],
              "value": "Upgrade to a patched version (the latest release 7.8.4, or the Sustain Release 7.6.3)"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Deserialization Vulnerability in GoAnywhere MFT\u0027s License Servlet",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\n\nImmediately ensure that access to the GoAnywhere Admin Console is not open to the public. Exploitation of this vulnerability is highly dependent upon systems being externally exposed to the internet. \n\n\u003c/span\u003e\n\n\u003cbr\u003e"
                }
              ],
              "value": "Immediately ensure that access to the GoAnywhere Admin Console is not open to the public. Exploitation of this vulnerability is highly dependent upon systems being externally exposed to the internet."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2025-10035",
        "datePublished": "2025-09-18T22:01:51.337Z",
        "dateReserved": "2025-09-05T16:43:32.877Z",
        "dateUpdated": "2026-08-04T03:55:56.207Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-8450 (GCVE-0-2025-8450)

    Vulnerability from cvelistv5 – Published: 2025-08-19 18:01 – Updated: 2025-08-29 20:09
    VLAI
    Title
    Unrestricted File Upload in FileCatalyst
    Summary
    Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-08-19 18:29 UTC
    CWE
    • CWE-434 - Unrestricted Upload of File with Dangerous Type
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    Fortra FileCatalyst Affected: 5.1.6 , ≤ 5.2.0 Build 80 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-8450",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-08-19T18:29:37.440894Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-08-19T18:30:00.515Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows",
                "MacOS",
                "Linux"
              ],
              "product": "FileCatalyst",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "5.2.0 Build 80",
                  "status": "affected",
                  "version": "5.1.6",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper Access Control issue in the Workflow component of Fortra\u0027s FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page."
                }
              ],
              "value": "Improper Access Control issue in the Workflow component of Fortra\u0027s FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-563",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-563 Add Malicious File to Shared Webroot"
                }
              ]
            },
            {
              "capecId": "CAPEC-650",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-650 Upload a Web Shell to a Web Server"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-29T20:09:24.656Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2025-010"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update to the latest version of FileCatalyst, Version 5.2.0 - Build 130"
                }
              ],
              "value": "Update to the latest version of FileCatalyst, Version 5.2.0 - Build 130"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Unrestricted File Upload in FileCatalyst",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2025-8450",
        "datePublished": "2025-08-19T18:01:14.137Z",
        "dateReserved": "2025-07-31T21:30:46.989Z",
        "dateUpdated": "2025-08-29T20:09:24.656Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-3871 (GCVE-0-2025-3871)

    Vulnerability from cvelistv5 – Published: 2025-07-16 14:00 – Updated: 2025-07-18 14:52
    VLAI
    Title
    Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier
    Summary
    Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this scenario, the attacker may enter the email address of a known user when prompted and the user will be disabled if that user has configured GOTP.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-18 14:52 UTC
    CWE
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere MFT Affected: 0 , < 7.8.1 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-3871",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-18T14:52:21.643028Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-07-18T14:52:28.197Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GoAnywhere MFT",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "7.8.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Broken access control in Fortra\u0027s GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this scenario, the attacker may enter the email address of a known user when prompted and the user will be disabled if that user has configured GOTP.\u0026nbsp;"
                }
              ],
              "value": "Broken access control in Fortra\u0027s GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this scenario, the attacker may enter the email address of a known user when prompted and the user will be disabled if that user has configured GOTP."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-151",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-151 Identity Spoofing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-07-16T14:00:27.665Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/FI-2025-009"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to GoAnwhere MFT 7.8.1 or higher"
                }
              ],
              "value": "Upgrade to GoAnwhere MFT 7.8.1 or higher"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cul\u003e\u003cli\u003e\u003cp\u003eEnsure all users configured to use GOTP email for 2FA already have an email set.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003eIn situations where the email cannot be set ahead of time (ex: Self-Registration), switch Admin and Web User Templates to use another 2FA option such as Time-based One-Time Password or RADIUS.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e"
                }
              ],
              "value": "*  Ensure all users configured to use GOTP email for 2FA already have an email set.\n\n\n  *  In situations where the email cannot be set ahead of time (ex: Self-Registration), switch Admin and Web User Templates to use another 2FA option such as Time-based One-Time Password or RADIUS."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2025-3871",
        "datePublished": "2025-07-16T14:00:27.665Z",
        "dateReserved": "2025-04-22T14:56:48.089Z",
        "dateUpdated": "2025-07-18T14:52:28.197Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-5141 (GCVE-0-2025-5141)

    Vulnerability from cvelistv5 – Published: 2025-06-17 19:30 – Updated: 2025-08-29 20:11
    VLAI
    Title
    Core Privileged Access Manager (BoKS) Leakage of Sensitive Data via the Cache
    Summary
    A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris allows low privilege local users to dump data from the cache.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-06-17 19:50 UTC
    CWE
    • CWE-524 - Use of Cache Containing Sensitive Information
    Impacted products
    Vendor Product Version
    Fortra Core Privileged Access Manager (BoKS) Affected: 0 , ≤ 7.2.0.17 (custom)
    Affected: 0 , ≤ 8.1.0.22 (custom)
    Affected: 0 , ≤ 8.1.1.7 (custom)
    Affected: 0 , ≤ 9.0.0.1 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-5141",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-06-17T19:50:23.706281Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-17T19:50:34.425Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Linux",
                "AIX",
                "Solaris"
              ],
              "product": "Core Privileged Access Manager (BoKS)",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "7.2.0.17",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.1.0.22",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "8.1.1.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "9.0.0.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Maciej Grabiec, ING Hubs Poland"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A binary in the BoKS Server Agent component of Fortra\u0027s Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris allows low privilege local users to dump data from the cache."
                }
              ],
              "value": "A binary in the BoKS Server Agent component of Fortra\u0027s Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris allows low privilege local users to dump data from the cache."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-204",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-204 Lifting Sensitive Data Embedded in Cache"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-524",
                  "description": "CWE-524: Use of Cache Containing Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-29T20:11:13.423Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2025-008"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to the latest patched version or hotfix"
                }
              ],
              "value": "Upgrade to the latest patched version or hotfix"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Core Privileged Access Manager (BoKS) Leakage of Sensitive Data via the Cache",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2025-5141",
        "datePublished": "2025-06-17T19:30:51.781Z",
        "dateReserved": "2025-05-23T21:18:11.239Z",
        "dateUpdated": "2025-08-29T20:11:13.423Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-11922 (GCVE-0-2024-11922)

    Vulnerability from cvelistv5 – Published: 2025-04-28 20:57 – Updated: 2025-04-28 22:27
    VLAI
    Title
    Input Validation vulnerability in Web Client emails that do not go through Secure Mail
    Summary
    Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert arbitrary HTML or JavaScript into an email.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-28 22:27 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere MFT Affected: 0 , ≤ 7.7.1 (custom)
    Create a notification for this product.
    Date Public
    2025-04-22 18:09
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-11922",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-28T22:27:45.719964Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-28T22:27:53.032Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows",
                "Linux",
                "64 bit",
                "iSeries",
                "IBM System P",
                "IBM z (Mainframe)",
                "UNIX"
              ],
              "product": "GoAnywhere MFT",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "7.7.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2025-04-22T18:09:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Missing input validation in certain features of the Web Client of Fortra\u0027s GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to\u0026nbsp;insert arbitrary HTML or JavaScript into an email."
                }
              ],
              "value": "Missing input validation in certain features of the Web Client of Fortra\u0027s GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to\u00a0insert arbitrary HTML or JavaScript into an email."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-63",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-63 Cross-Site Scripting (XSS)"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or \u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-28T20:57:37.388Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2025-005"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to version 7.8.0"
                }
              ],
              "value": "Upgrade to version 7.8.0"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Input Validation vulnerability in Web Client emails that do not go through Secure Mail",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgba(9, 30, 66, 0.055);\"\u003eLimit access to only trustworthy Web Users\u003c/span\u003e\n\n\u003cbr\u003e"
                }
              ],
              "value": "Limit access to only trustworthy Web Users"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2024-11922",
        "datePublished": "2025-04-28T20:57:37.388Z",
        "dateReserved": "2024-11-27T18:20:19.664Z",
        "dateUpdated": "2025-04-28T22:27:53.032Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-0049 (GCVE-0-2025-0049)

    Vulnerability from cvelistv5 – Published: 2025-04-28 20:55 – Updated: 2025-04-28 22:28
    VLAI
    Title
    Disclosure of sensitive information in an error message in GoAnywhere prior to version 7.8.0
    Summary
    When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-28 22:28 UTC
    CWE
    • CWE-209 - Generation of Error Message Containing Sensitive Information
    References
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere Affected: 0 , < 7.8 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-0049",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-28T22:28:02.231778Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-28T22:28:10.671Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GoAnywhere",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "7.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow\u0026nbsp;Fuzzing for application mapping.\u003cbr\u003e\u003cp\u003eThis issue affects GoAnywhere: before 7.8.0.\u003c/p\u003e"
                }
              ],
              "value": "When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow\u00a0Fuzzing for application mapping.\nThis issue affects GoAnywhere: before 7.8.0."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-215",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-215 Fuzzing for application mapping"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.5,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-209",
                  "description": "CWE-209 Generation of Error Message Containing Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-28T20:55:06.256Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2025-004"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to GoAnywhere 7.8.0 or later."
                }
              ],
              "value": "Upgrade to GoAnywhere 7.8.0 or later."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Disclosure of sensitive information in an error message in GoAnywhere prior to version 7.8.0",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This issue occurs when the Web User does not have Create permission on Subfolders. It is a bug that happens when a user tries to upload a file to a directory that doesn\u2019t exist yet (If they have permissions to create sub directories, then the non-existent directory would be created automatically).\u003cbr\u003e\u003cbr\u003eNote: This workaround requires supplying an additional permission that the Web User does not have in vulnerable configurations.\u0026nbsp;"
                }
              ],
              "value": "This issue occurs when the Web User does not have Create permission on Subfolders. It is a bug that happens when a user tries to upload a file to a directory that doesn\u2019t exist yet (If they have permissions to create sub directories, then the non-existent directory would be created automatically).\n\nNote: This workaround requires supplying an additional permission that the Web User does not have in vulnerable configurations."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2025-0049",
        "datePublished": "2025-04-28T20:55:06.256Z",
        "dateReserved": "2024-11-27T18:20:36.029Z",
        "dateUpdated": "2025-04-28T22:28:10.671Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-11923 (GCVE-0-2024-11923)

    Vulnerability from cvelistv5 – Published: 2025-01-17 23:44 – Updated: 2025-01-22 14:25
    VLAI
    Title
    Sensitive Information Disclosure in Fortra Application Hub Prior to version 1.3
    Summary
    Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One) prior to version 1.3
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-22 14:24 UTC
    CWE
    • CWE-532 - Insertion of Sensitive Information into Log File
    Impacted products
    Vendor Product Version
    Fortra Fortra Application Hub Affected: 1.0 , ≤ 1.2 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-11923",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-22T14:24:57.571658Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-22T14:25:10.620Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Fortra Application Hub",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "1.2",
                  "status": "affected",
                  "version": "1.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Under certain log settings the IAM or CORE service will log credentials in the iam logfile in\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eFortra Application Hub (Formerly named Helpsystems One) prior to version 1.3\u003c/span\u003e"
                }
              ],
              "value": "Under certain log settings the IAM or CORE service will log credentials in the iam logfile in\u00a0Fortra Application Hub (Formerly named Helpsystems One) prior to version 1.3"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-215",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-215 Fuzzing for application mapping"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-532",
                  "description": "CWE-532 Insertion of Sensitive Information into Log File",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-17T23:44:06.075Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2025-003"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to Fortra Application Hub 1.3 or higher."
                }
              ],
              "value": "Upgrade to Fortra Application Hub 1.3 or higher."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Sensitive Information Disclosure in Fortra Application Hub Prior to version 1.3",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Avoid using \"trace\" logging levels in Fortra Application Hub\u0026nbsp;"
                }
              ],
              "value": "Avoid using \"trace\" logging levels in Fortra Application Hub"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2024-11923",
        "datePublished": "2025-01-17T23:44:06.075Z",
        "dateReserved": "2024-11-27T18:20:21.571Z",
        "dateUpdated": "2025-01-22T14:25:10.620Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-9945 (GCVE-0-2024-9945)

    Vulnerability from cvelistv5 – Published: 2024-12-13 15:22 – Updated: 2025-08-29 20:18
    VLAI
    Title
    Limited Information Disclosure in GoAnywhere MFT Prior to 7.7.0
    Summary
    An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-13 17:35 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    • CWE-425 - Direct Request ('Forced Browsing')
    • CWE-552 - Files or Directories Accessible to External Parties
    References
    Impacted products
    Vendor Product Version
    Fortra GoAnywhere MFT Affected: 0 , < 7.7.0 (custom)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9945",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-13T17:35:02.426621Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-13T17:35:32.342Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows",
                "Linux",
                "64 bit",
                "iSeries",
                "IBM System P",
                "IBM z (Mainframe)",
                "UNIX"
              ],
              "product": "GoAnywhere MFT",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThan": "7.7.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "xiao xiong"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An information-disclosure vulnerability exists in Fortra\u0027s GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.\u0026nbsp;\u0026nbsp;\u003cbr\u003e"
                }
              ],
              "value": "An information-disclosure vulnerability exists in Fortra\u0027s GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-87",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-87 Forceful Browsing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-425",
                  "description": "CWE-425 Direct Request (\u0027Forced Browsing\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-552",
                  "description": "CWE-552 Files or Directories Accessible to External Parties",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-08-29T20:18:10.908Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2024-014"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to GoAnywhere 7.7.0 or higher."
                }
              ],
              "value": "Upgrade to GoAnywhere 7.7.0 or higher."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Limited Information Disclosure in GoAnywhere MFT Prior to 7.7.0",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2024-9945",
        "datePublished": "2024-12-13T15:22:31.536Z",
        "dateReserved": "2024-10-14T17:47:11.055Z",
        "dateUpdated": "2025-08-29T20:18:10.908Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3334 (GCVE-0-2024-3334)

    Vulnerability from cvelistv5 – Published: 2024-11-15 19:57 – Updated: 2024-11-15 21:11
    VLAI
    Title
    USB Security Feature Bypass in Digital Guardian Windows Agent Prior to version 8.2.0
    Summary
    A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby compromising the confidentiality of the stored data.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-15 21:11 UTC
    CWE
    • CWE-922 - Insecure Storage of Sensitive Information
    Impacted products
    Vendor Product Version
    Fortra Digital Guardian Agent Affected: 7.9.4 , ≤ 8.1.0 (semverCWE-693: Protection Mechanism Failure)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3334",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-15T21:11:37.124030Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-15T21:11:54.745Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "RME"
              ],
              "platforms": [
                "Windows"
              ],
              "product": "Digital Guardian Agent",
              "vendor": "Fortra",
              "versions": [
                {
                  "lessThanOrEqual": "8.1.0",
                  "status": "affected",
                  "version": "7.9.4",
                  "versionType": "semverCWE-693: Protection Mechanism Failure"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby compromising the confidentiality of the stored data.\u003cbr\u003e\u003cbr\u003e\u003cp\u003e\u003cbr\u003e\u003c/p\u003e"
                }
              ],
              "value": "A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby compromising the confidentiality of the stored data."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-554",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-554 Functionality Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "PHYSICAL",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-922",
                  "description": "CWE-922 Insecure Storage of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-15T19:57:28.245Z",
            "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
            "shortName": "Fortra"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.fortra.com/security/advisories/product-security/fi-2024-013"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.fortra.com/endpoint-dlp/kb-articles/dg-support-notice-security-bypass-vulnerability-with-rme-MTQwYTM5NTctZDk4Ny1lZjExLWFjMjEtNjA0NWJkMDFhMzQ3"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eThere are two things required to remediate the bypass:\u003c/div\u003e\u003cdiv\u003e1. Upgrade the Windows Agent to version 8.2.0 or above.\u003c/div\u003e\u003cdiv\u003e2. Apply a new RME rule. For additional details, please see this \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://support.fortra.com/endpoint-dlp/kb-articles/dg-support-notice-security-bypass-vulnerability-with-rme-MTQwYTM5NTctZDk4Ny1lZjExLWFjMjEtNjA0NWJkMDFhMzQ3\"\u003eknowledge base article\u003c/a\u003e.\u003c/div\u003e"
                }
              ],
              "value": "There are two things required to remediate the bypass:\n\n1. Upgrade the Windows Agent to version 8.2.0 or above.\n\n2. Apply a new RME rule. For additional details, please see this  knowledge base article https://support.fortra.com/endpoint-dlp/kb-articles/dg-support-notice-security-bypass-vulnerability-with-rme-MTQwYTM5NTctZDk4Ny1lZjExLWFjMjEtNjA0NWJkMDFhMzQ3 ."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "USB Security Feature Bypass in Digital Guardian Windows Agent Prior to version 8.2.0",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "assignerShortName": "Fortra",
        "cveId": "CVE-2024-3334",
        "datePublished": "2024-11-15T19:57:28.245Z",
        "dateReserved": "2024-04-04T17:41:13.489Z",
        "dateUpdated": "2024-11-15T21:11:54.745Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }